VDB
Sign up
MEDIUM6.5

GHSA-mmwx-rj87-vfgr

DNSJava affected by KeyTrap - NSEC3 closest encloser proof can exhaust CPU resources

Quick fix

GHSA-mmwx-rj87-vfgr — dnsjava:dnsjava: upgrade to the fixed version with the command below.

# pom.xml: bump <version>3.6.0</version> for dnsjava:dnsjava

Details

### Impact Users using the `ValidatingResolver` for DNSSEC validation can run into CPU exhaustion with specially crafted DNSSEC-signed zones.

### Patches Users should upgrade to dnsjava v3.6.0

### Workarounds Although not recommended, only using a non-validating resolver, will remove the vulnerability.

### References https://www.athene-center.de/en/keytrap

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/dnsjava:dnsjava
Introduced in: 3.5.0Fixed in: 3.6.0
Fix# pom.xml: bump <version>3.6.0</version> for dnsjava:dnsjava
Maven/org.jitsi:dnssecjava
Introduced in: 0

No fixed version published yet for org.jitsi:dnssecjava (maven). Pin to a known-safe version or switch to an alternative.

References